15 findings credited to this research

Each row is an advisory published by someone else whose credit names this research as the reporter. The link on every identifier goes to the source that establishes the credit, not to a summary of it.

These are external credits. The dossiers this platform researches and writes itself are research records, and the advisories derived from them are indexed separately.

The shape of the work

Every figure below is counted from the 15 verified credits on this page - not sampled, not projected. Selecting a value emphasises the findings that carry it; nothing is ever hidden.

Verified findings

15

across 15 projects, each named in an advisory published by someone else

High severity

8

of 15, by the advisory's own band

high 8 · medium 6 · low 1

Fixes shipped

14

of 15 name the release carrying the fix

1 has a full record here

What keeps recurring

Findings by weakness class. Only 2 classes appear more than once.

10 further classes with 10 findings between them, each appearing once.

202615 credits

  1. CVE-2026-70622, credit evidence on CVE Program

    tar-rsRust (crates.io)CWE-59, Improper Link Resolution Before File Access ('Link Following'), on MITRE CWEhigh

    Symlink escape in Builder::append_dir_all allows a privileged process to read a file outside the intended root into the archive.

    Fixed in0.4.47Write-up
  2. CVE-2026-68930, credit evidence on GitHub Security Advisories

    russhRust (crates.io)CWE-666, Operation on Resource in Wrong Phase of Lifetime, on MITRE CWEmedium

    Operation on a resource after expiry, with an authorization check that could be bypassed.

    Fixed in0.62.5
  3. CVE-2026-67320, credit evidence on CVE Program

    axiosnpmCWE-1321, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), on MITRE CWEhigh

    Prototype pollution reachable through request handling, leading to information exposure.

    Fixed in1.18.0
  4. CVE-2026-59896, credit evidence on GitHub Security Advisories

    hononpmCWE-362, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), on MITRE CWEmedium

    Race condition in request handling.

    Fixed in4.12.27
  5. CVE-2026-48525, credit evidence on GitHub Security Advisories

    PyJWTPyPICWE-400, Uncontrolled Resource Consumption, on MITRE CWEmedium

    Uncontrolled resource consumption when decoding a crafted token.

    Fixed in2.13.0
  6. CVE-2026-45784, credit evidence on GitHub Security Advisories

    rust-opensslRust (crates.io)CWE-131, Incorrect Calculation of Buffer Size, on MITRE CWEmedium

    Incorrect calculation of buffer size leading to an out-of-bounds write.

    Fixed in0.10.80
  7. CVE-2026-45539, credit evidence on GitHub Security Advisories

    microsoft/apmGoCWE-59, Improper Link Resolution Before File Access ('Link Following'), on MITRE CWEhigh

    Symlink following on an output path, exposing information outside the intended location.

    Fixed in0.13.0
  8. CVE-2026-44724, credit evidence on GitHub Security Advisories

    systeminformationnpmCWE-78, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), on MITRE CWEhigh

    Command injection through unsanitised input reaching process execution.

    Fixed in5.31.6
  9. CVE-2026-44240, credit evidence on GitHub Security Advisories

    basic-ftpnpmCWE-400, Uncontrolled Resource Consumption, on MITRE CWEhigh

    Uncontrolled resource consumption from an unbounded allocation.

    Fixed in5.3.1
  10. CVE-2026-39360, credit evidence on GitHub Security Advisories

    RustFSRust (crates.io)CWE-862, Missing Authorization, on MITRE CWEmedium

    Missing authorization on a request path.

  11. CVE-2026-34601, credit evidence on GitHub Security Advisories

    @xmldom/xmldomnpmCWE-91, XML Injection (aka Blind XPath Injection), on MITRE CWEhigh

    XML injection through incorrectly neutralised markup.

    Fixed in0.9.9
  12. CVE-2026-32936, credit evidence on GitHub Security Advisories

    CoreDNSGoCWE-400, Uncontrolled Resource Consumption, on MITRE CWEhigh

    Uncontrolled resource consumption reachable from a crafted request.

    Fixed in1.14.3
  13. CVE-2026-32808, credit evidence on GitHub Security Advisories

    pyload-ngPyPICWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), on MITRE CWEhigh

    Path traversal during encrypted 7z password verification allowed a file outside the extraction directory to be deleted.

    Fixed in0.5.0b3.dev97TSS-R-2026-001
  14. CVE-2026-25500, credit evidence on GitHub Security Advisories

    RackRubyGemsCWE-79, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), on MITRE CWEmedium

    Stored cross-site scripting from input that was not correctly sanitised.

    Fixed in3.2.5
  15. CVE-2026-10722, credit evidence on GitHub Security Advisories

    cilium/ebpfGoCWE-190, Integer Overflow or Wraparound, on MITRE CWElow

    Integer overflow in BTF length checking.

    Fixed in0.22.0